Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Rise Zap

affifnliolaibgojgliojpifcebcopla
Risk Score
4.63
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3
Rating 5.0
Last updated 2026-06-02 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer ajudarisecommunity@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own generic policy — not scoped to this extension, yet admits data collection and third-party sharing (+10 privacy).
  • Brand impersonation: extension claims WhatsApp integration, developer domain is gmail.com, not Meta/WhatsApp.
  • Free-webmail developer (gmail.com) with no verified business website raises accountability concerns.
  • Content script runs on web.whatsapp.com with no CSP — two innerHTML DOM-XSS sinks present; WhatsApp session data at risk.
  • 3 installs with non-trivial host access to WhatsApp Web and a Supabase backend — tail attack surface concern.

Evidence

  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — not extension-scoped; data_collection=true, third_party_sharing=true.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true; developer domain gmail.com, not confirmed owner of WhatsApp brand.
  • free_webmail_developer store Developer email ajudarisecommunity@gmail.com — free webmail, no verified business site.
  • dom_xss_no_csp crx Two innerHTML sinks in content scripts running on web.whatsapp.com; csp_present=false increases XSS risk.
  • supabase_backend_host manifest host_permissions include txnhtcyjzohxkfwdfrvh.supabase.co — unverifiable third-party DB with user data access.
  • very_low_install_count store Only 3 installs; extension is essentially untested by community, reputation signals absent.
  • no_csp_mv3 manifest content_security_policy=null on MV3; no explicit CSP hardening despite DOM-sink findings.
  • wayback_no_snapshot api No Wayback Machine snapshot; developer domain history unverifiable.

Permissions Breakdown

  • storage low Stores local extension state; low risk.
  • alarms low Schedules periodic tasks; low risk.
  • https://web.whatsapp.com/* medium Content-script and request access to WhatsApp Web — can read/send messages on user's behalf.
  • https://txnhtcyjzohxkfwdfrvh.supabase.co/* medium Direct access to a Supabase backend; data may be exfiltrated to this third-party DB.
  • https://risezap.online/* medium Access to developer's own domain; risk depends on trustworthiness of that domain.

Pillar Scores

Permissions2.30
Reputation7.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 05:13
Listing SHA 3c110e445d43…
Force block — not fired
Score recovered no
Elapsed